A stack buffer overflow vulnerability was found in GStreamers DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.6 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | gstreamer1-plugins-bad-free-0:1.24.11-3.el10_0.6 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | gstreamer1-plugins-bad-free-0:1.10.4-7.el7_9 | * |
| Red Hat Enterprise Linux 8 | RedHat | gstreamer1-plugins-bad-free-0:1.16.1-9.el8_10.1 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | gstreamer1-plugins-bad-free-0:1.16.1-4.el8_6.4 | * |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | RedHat | gstreamer1-plugins-bad-free-0:1.16.1-4.el8_6.4 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | gstreamer1-plugins-bad-free-0:1.16.1-4.el8_8.4 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | gstreamer1-plugins-bad-free-0:1.16.1-4.el8_8.4 | * |
| Red Hat Enterprise Linux 9 | RedHat | gstreamer1-plugins-bad-free-0:1.22.12-7.el9_8.3 | * |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | RedHat | gstreamer1-plugins-bad-free-0:1.22.1-6.el9_4.6 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | gstreamer1-plugins-bad-free-0:1.22.12-5.el9_6.6 | * |
| Gst-plugins-bad1.0 | Ubuntu | questing | * |